Types of Spoofing attacks Flashcards
What is ARP Spoofing and what countermeasures can be applied?
Faking the mapping between IP and MAC
- Send fake ARP request or response
- The target receives the wrong IP-MAC mapping
Countermeasures:
Client: Static IP-MAC mapping
Switch and gateway: static port-MAC mapping
Periodically check ARP caching
Firewall: monitor the ARP caching
What is router spoofing and how can it be countered?
Routing protocols
Countermeasures: router and routes authentication
What is IP spoofing and what countermeasures can be applied?
The creation of IP packets with a false source IP address, for the purpose of impersonating another computing system.
Countermeasures:
- Use random ISN
- Use encryption-based protocols, IPSec, SSH/TLS
- Use password or certificate authentication
- Use packet filtering on routers
- Don’t use trust policies based on IP addresses